Iranian general accuses Siemens of helping U.S., Israel build Stuxnet
Suggests Iran may file charges in international courts
Computerworld - An Iranian military commander Saturday accused the German electronics giant Siemens with helping U.S. and Israeli teams craft the Stuxnet worm that attacked his country's nuclear facilities.
According to the Islamic Republic News Service (IRNA), Iran's state news agency, Brigadier General Gholam Reza Jalali laid some of the blame for Stuxnet on Siemens.
"Siemens should explain why and how it provided the enemies with the information about the codes of the SCADA software and prepared the ground for a cyber attack against us," Jalali told IRNA.
Siemens did not reply to a request for comment on Jalali's accusations.
Jalali heads Iran's Passive Defense Organization, a military unit responsible for constructing and defending the country's nuclear enrichment facilities. He is a former commander in Iran's Revolutionary Guard.
Stuxnet, which first came to light in June 2010 but hit Iranian targets in several waves starting the year before, has been extensively analyzed by security researchers, most notably a three-man team at Symantec, and by Ralph Langner of the German firm Langner Communications GmbH.
According to both Symantec and Langner, Stuxnet was designed to infiltrate Iran's nuclear enrichment program, hide in the Iranian SCADA (supervisory control and data acquisition) control systems that operate its plants, then force gas centrifuge motors to spin at unsafe speeds. Gas centrifuges, which are used to enrich uranium, can fly apart if spun too fast.
Jalali suggested that Iranian officials would pursue Siemens in the courts.
"The Foreign Ministry and other relevant political and judicial organizations should lodge complaints at international courts," said Jalali. "The attacking countries should be held legally responsible for the cyberattack."
He also claimed that Iranian researchers had traced the attack to Israel and the U.S. "The investigations and research showed that the Stuxnet worm had been disseminated from sources in the U.S. and Israel," said Jalali, who added that the worm sent reports of infected systems to computers in Texas.
Jalali's allegations of U.S. and Israeli involvement were the first from an Iranian official, although President Mahmoud Ahmadinejad has repeatedly blamed the two countries for trying to destabilize his government.
In January, the New York Times, citing confidential sources, said that Stuxnet was jointly created by the U.S. and Israel, with the latter using its covert nuclear facility at Dimona to test the worm's effectiveness on centrifuges like the ones Iran employs.
According to the Times, Siemens cooperated in 2008 with the Idaho National Laboratory (INL) to help experts there identify vulnerabilities in the SCADA hardware and software sold by the German firm. The lab -- located about 30 miles east of Idaho Falls, Idaho -- is the U.S. Department of Energy's lead nuclear research facility.
Jalali repeated earlier claims by others in Iran, including Ahmadinejad, that Stuxnet did not cause major damage or disrupt its nuclear enrichment program because researchers discovered the worm and instituted defenses.
"If we were not ready to tackle the crisis and their attack was successful, the attack could have created tragic incidents at the country's industrial sites and refineries," said Jalali.
He suggested that massive casualties could have resulted, and suggested that they might have been on the scale of the Bhopal, India disaster, where in 1984 a Union Carbide pesticide plant released chemicals that killed between 4,000 and 8,000 people.
Symantec, however, has said that Stuxnet was very successful. In a February update to its research on the worm, Symantec said the first attacks in June 2009 infected Iranian computers just 12 hours after the worm was compiled. The average time between compilation and infection was 19 days for the 10 successful attacks Symantec monitored over an 11-month span.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
Cyberattacks
- Update: Chinese hackers breached U.S. Chamber of Commerce
- DHS sees no evidence of cyberattack on Ill. water facility
- 4 lessons from the Springfield, Ill. SCADA cyberattack
- Despite Stuxnet, Duqu, control system flaws still overlooked
- DHS issues warning that Anonymous may attack infrastructure
- China denies role in hack of Japanese defense contractor
- RSA spearphish attack may have hit U.S. defense organizations
- 10 years after 9/11, cyberattacks pose national threat, committee says
- DHS warns of planned Anonymous attacks
- DHS warns that Irene could prompt phishing scams
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Expert Guide to Secure Your Active Directory
- Layered security is the way to go when it comes to protecting Active Directory. This expert e-guide explains the best method to use...
- ESG Lab Validation Report: HP Data Protector & Deduplication Solutions
- Many organizations have deployed disk-to-disk backup technologies to improve the speed and reliability of their backup and disaster recovery operations. A growing number...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts
